Perhaps. Are _all_ sessions attributes hidden within the 'protected' part? And what about request attributes for instance? You might be able to use session or request actions to store the userid under a different name in session or request context outside the protected part.

If that doesn't help, try asking the dev list...

Kind regards,
Geert

Derek Hohls wrote:

Geert
Thanks... any suggestion for a work-around in the meantime?? Thanks
Derek

---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]